Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cato CTRL Threat Brief: AI, Zero-Days, and the US-China Cyber Arms Race

Underlying the US–China AI race, there’s arguably a more sinister arms race—the race to identify zero-day threats. Frontier AI algorithms, such as Anthropic Mythos (here) and China’s Qihoo 360 (here), are compressing the zero-day discovery cycle. But how those discoveries are gathered and shared among cooperating entities is giving China significant defensive and offensive advantages.

BlackToad: Network Manipulation in an AutoIt Payload

Recently, JUMPSEC’s DART (Detection and Response Team) detected a phishing email targeting a client environment. The email, written in Thai and containing a MediaFire download link, was identified as suspicious by an incident responder and we kicked off an investigation. Since then, we have established infrastructure to track the threat actor, analysed the novel payload in detail, and identified several IoCs below.

Three ways intelligent workflows enhance network security

Network security is operationally complex. It involves constant triage, approvals, and monitoring, spread across a range of tools, teams, and environments. Traditionally, this requires teams to do a significant amount of time-consuming, repetitive, and draining manual work, resulting in a longer MTTR and leaving many practitioners overwhelmed and burnt out. The problem isn’t in the tools they use – it’s in the work that happens between tools.

Invisible Cross-Tracking: How Mobile Apps Share Your Data and How to Stop It

Tracking user activity across apps on mobile devices is crucial, as data no longer flows from a single source on phones. For example, in the span of an hour, a user might open Instagram, Gmail, a shopping app, a weather app, and a free game, while various advertising tools quietly analyze network signals, device behavior, location data, and app usage patterns. A VPN won't remove every unique identifier in these apps, but it does make it harder to connect one link in this tracking chain: the digital network footprint.

Stop Treating AI Like Another SaaS App

Employees are leveraging AI to boost productivity and adopt skills that would take years to learn. This ranges from drafting content, writing code, and building automated workflows. Some of this use is approved. Much of it is not. For many security teams, the first instinct is to treat this risk like they would any other SaaS risk: discover the app, allow or block access, apply DLP rules, and report on usage. That model works for traditional SaaS, but AI is different.

How to Safely Buy a Residential Proxy Without Leaking Data: A Checklist for Affiliates and SEO

The world of traffic arbitrage and SEO promotion today resembles a minefield, where every wrong move costs money. Beginners often make the fatal mistake of trusting the first free or suspiciously cheap service they come across.

Is Public Wi-Fi Safe? 7 Top Tips for Surfing Safely on the Web

We rarely find ourselves without access to the Internet, thanks to the increased number of public Wi-Fi networks or hotspots wherever we go. From our local coffee shops, libraries, or shopping centers, connecting to the web is easier than ever. But is it more secure? Since 2019, the rise of remote workers and digital nomads means we are more reliant on public Wi-Fi to get our jobs done and to carry out our daily tasks, from online shopping, to emails and video conferences.

A Deep Dive Into The Multi Cloud Mess & How AlgoSec Connects the Dots

Multi cloud environments were supposed to deliver flexibility and scalability, but for many organizations they have created fragmented visibility, inconsistent security policies, cloud sprawl, and growing operational risk. In this video, we take a deep dive into the modern multi cloud security challenge and explore how AlgoSec helps organizations connect the dots across AWS, Azure, GCP, Kubernetes, and on premises environments.